Courseiva

MS-102 Deploy and manage a Microsoft 365 tenant Practice Question

You are the Microsoft 365 administrator for a company that uses Microsoft 365 E5. The company has a hybrid identity environment with Microsoft Entra Connect Sync. You need to implement Microsoft Entra Password Protection to prevent users from using weak passwords. You must ensure that the on-premises Active Directory Domain Services (AD DS) environment enforces the same password policies as Microsoft Entra ID. What should you do? (Choose two.)

⚠ Common exam trap

The trap here is assuming that password hash synchronization is required or that the proxy service should be installed on a domain controller, which are common misconceptions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Install the Microsoft Entra Password Protection proxy service on a server in the on-premises network.

To enforce Microsoft Entra Password Protection on-premises, you must deploy both the proxy service and the DC agent. The proxy service enables communication with Microsoft Entra ID to retrieve the password policies, and the DC agent on each domain controller enforces those policies during password changes. Password hash synchronization is not required, and the proxy service must not be installed on a domain controller. These two components work together to extend Microsoft Entra Password Protection to the on-premises AD DS environment.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Install the Microsoft Entra Password Protection proxy service on a server in the on-premises network.

    Why this is correct

    The Microsoft Entra Password Protection proxy service is required to enable on-premises domain controllers to communicate with Microsoft Entra ID for password policy enforcement. The proxy service acts as a bridge between the on-premises environment and Microsoft Entra ID, forwarding password validation requests. Without the proxy, the domain controllers cannot access the global banned password list or custom banned lists. This component is essential for the on-premises enforcement of Microsoft Entra Password Protection.

  • ✗

    Enable password hash synchronization in Microsoft Entra Connect.

    Why it's wrong here

    Password hash synchronization is not required for Microsoft Entra Password Protection. Password hash synchronization synchronizes password hashes from on-premises AD DS to Microsoft Entra ID for authentication, but it does not enforce password policies on-premises. Microsoft Entra Password Protection works independently of password hash synchronization and can be used with or without it. Enabling password hash synchronization would not help meet the requirement to enforce the same password policies on-premises.

  • ✗

    Configure the on-premises domain controllers to use the Microsoft Entra Password Protection proxy service as a forwarder.

    Why it's wrong here

    The proxy service is not configured as a forwarder on domain controllers. Instead, the DC agent on each domain controller communicates with the proxy service to retrieve password policies. The proxy service is installed on a member server, not on domain controllers, and it does not act as a DNS or authentication forwarder. Configuring domain controllers to use the proxy as a forwarder is not a supported configuration and would not enable password protection.

  • ✗

    Install the Microsoft Entra Password Protection proxy service on a domain controller.

    Why it's wrong here

    The proxy service should not be installed on a domain controller. It is recommended to install the proxy service on a member server that is not a domain controller to avoid performance and security issues. The proxy service requires network access to Microsoft Entra ID and should be isolated from the domain controller role. Installing it on a domain controller could introduce unnecessary overhead and potential security risks, and it is not a supported best practice.

  • ✓

    Install the Microsoft Entra Password Protection DC agent on all domain controllers.

    Why this is correct

    The Microsoft Entra Password Protection DC agent must be installed on each domain controller to enforce the password policy. The DC agent receives password policy from the proxy service and applies it during password changes. It also caches the policy locally so that if the proxy is unavailable, the domain controllers can still enforce the last known policy. Installing the DC agent on all domain controllers ensures consistent enforcement across the domain.

About these practice questions

One of 712 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.